27% of FFIEC Cybersecurity Assessment Tool (CAT) you already have
OWASP DevSecOps Maturity Model (DSOMM) already covers about 27% of FFIEC Cybersecurity Assessment Tool (CAT), leaving
36 of 49 controls as genuinely new work.
Already covered 10
Likely covered 3
New work 36
What is genuinely new work
Nothing in OWASP DevSecOps Maturity Model (DSOMM) reaches these. This is the list to scope.
CAT-D2-3Information sharing
CAT-D4-2Relationship management
CAT-D5-2Detection, response, and mitigation
CAT-D5-3Escalation and reporting
CAT-IRP-1Technologies and connection types
CAT-IRP-2Delivery channels
CAT-IRP-3Online/mobile products and technology services
FFIEC-CAT-CC-1Cybersecurity Controls - Preventive Controls Infrastructure Management
FFIEC-CAT-CC-2Cybersecurity Controls - Access and Data Management
FFIEC-CAT-CC-3Cybersecurity Controls - Detective Controls
FFIEC-CAT-CC-4Cybersecurity Controls - Corrective Controls Patch Management
FFIEC-CAT-CRI-1Migration Path to CRI Profile
FFIEC-CAT-CRMO-1Cyber Risk Management and Oversight - Governance
FFIEC-CAT-CRMO-2Risk Management Program
FFIEC-CAT-CRMO-3Resources and Training
FFIEC-CAT-CRMO-4Culture and Accountability
FFIEC-CAT-EDM-1External Dependency Management - Connections
FFIEC-CAT-EDM-2External Dependency Management - Relationship Management
FFIEC-CAT-IM-1Incident Management - Incident Resilience Planning and Strategy
FFIEC-CAT-IM-2Incident Management - Detection, Response, and Mitigation
FFIEC-CAT-IM-3Incident Management - Escalation and Reporting
FFIEC-CAT-IRP-1Inherent Risk Profile - Technologies and Connection Types
FFIEC-CAT-IRP-2Inherent Risk Profile - Delivery Channels
FFIEC-CAT-IRP-3Online or Mobile Products and Technology Services
FFIEC-CAT-IRP-4Organizational Characteristics
FFIEC-CAT-IRP-5External Threats
FFIEC-CAT-TI-1Threat Intelligence - Intelligence and Information
FFIEC-CAT-TI-2Threat Intelligence - Monitoring and Analyzing
FFIEC-CAT-TI-3Threat Intelligence - Information Sharing
Show the 13 you already have
CAT-D1-4Training and culture
CAT-D2-1Threat intelligence
CAT-D2-2Monitoring and analyzing
CAT-D3-1Preventative controls
CAT-D3-2Detective controls
CAT-D3-3Corrective controls
CAT-D4-3Third-party access controls
CAT-D5-1Incident planning and strategy
CAT-IRP-4Organizational characteristics
CAT-IRP-5External threats
CAT-D5-4Resilience planning and testing
How this is calculated
Already covered means a mapping runs from a control in OWASP DevSecOps Maturity Model (DSOMM) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition